Ver Mensaje Individual
  #1  
Antiguo 23-feb-2008, 05:02
tu_papa tu_papa está desconectado
Junior Member
 
Fecha de Ingreso: febrero-2008
Mensajes: 1
Predeterminado

mi pc esta muy lenta creo que esta infectada pase el combofis y me sale esto

ComboFix 08-01-23.2 - User 2008-02-21 15:36:15.4 - NTFSx86

Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.487 [GMT 0:00]

Running from: C:\Documents and Settings\User\Desktop\ComboFix.exe



WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

.



((((((((((((((((((((((((( Files Created from 2007-12-23 to 2008-01-23 )))))))))))))))))))))))))))))))

.



2008-01-23 15:29 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\Nircmd.exe

2008-01-21 20:44 . 2008-01-21 20:44 268 --ah----- C:\sqmdata07.sqm

2008-01-21 20:44 . 2008-01-21 20:44 244 --ah----- C:\sqmnoopt07.sqm

2008-01-20 21:53 . 2008-01-20 21:53 <DIR> d-------- C:&#092;Program Files&#092;MSXML 6.0

2008-01-20 21:44 . 2008-01-20 21:44 <DIR> d-------- C:&#092;Program Files&#092;MSXML 4.0

2008-01-20 14:59 . 2008-01-20 14:59 <DIR> d-------- C:&#092;WINDOWS&#092;system32&#092;Kaspersky Lab

2008-01-20 12:57 . 2008-01-20 12:57 <DIR> d-------- C:&#092;Program Files&#092;SigmaTel

2008-01-20 12:57 . 2008-01-20 12:57 <DIR> d-------- C:&#092;Program Files&#092;Sierra

2008-01-20 12:57 . 2008-01-20 12:57 <DIR> d-------- C:&#092;Program Files&#092;HP

2008-01-20 12:57 . 2008-01-20 12:57 <DIR> d-------- C:&#092;Program Files&#092;Hewlett-Packard

2008-01-20 12:57 . 2008-01-20 12:57 <DIR> d-------- C:&#092;PatchTrlm14RevB

2008-01-20 12:57 . 2008-01-20 12:57 <DIR> d-------- C:&#092;Kontiki

2008-01-20 12:03 . 2008-01-20 12:03 <DIR> d-------- C:&#092;Program Files&#092;Disk Space Visualizer

2008-01-20 11:34 . 2002-12-29 01:14 81,920 --a------ C:&#092;WINDOWS&#092;system32&#092;Startup.cpl

2008-01-17 20:07 . 2008-01-17 20:07 <DIR> d-------- C:&#092;Program Files&#092;Windows Defender

2008-01-16 00:05 . 2008-01-16 00:06 <DIR> d-------- C:&#092;WINDOWS&#092;ERUNT

2008-01-13 17:53 . 2008-01-13 17:53 <DIR> d-------- C:&#092;Program Files&#092;Java

2008-01-13 17:53 . 2008-01-13 17:53 <DIR> d-------- C:&#092;Program Files&#092;Common Files&#092;Java

2008-01-13 17:53 . 2007-09-24 23:31 69,632 --a------ C:&#092;WINDOWS&#092;system32&#092;javacpl.cpl

2007-12-28 00:46 . 2007-12-28 14:54 20 --a------ C:&#092;WINDOWS&#092;system32&#092;Rmvirus.lst

2007-12-27 13:17 . 2005-09-23 08:29 626,688 --a------ C:&#092;WINDOWS&#092;system32&#092;msvcr80.dll

2007-12-25 18:11 . 2005-05-26 15:34 2,297,552 --a------ C:&#092;WINDOWS&#092;system32&#092;d3dx9_26.dll

2007-12-25 17:55 . 2007-12-25 17:55 <DIR> d-------- C:&#092;Program Files&#092;Microsoft Games



.

(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))

.

2008-01-20 21:46 --------- d-----w C:&#092;Program Files&#092;Microsoft IntelliPoint

2008-01-20 12:30 --------- d--h--w C:&#092;Program Files&#092;InstallShield Installation Information

2008-01-20 12:27 --------- d-----w C:&#092;Program Files&#092;Common Files&#092;Adobe

2008-01-20 12:13 --------- d-----w C:&#092;Program Files&#092;DivX

2008-01-17 23:01 --------- d-----w C:&#092;Program Files&#092;Common Files&#092;Real

2008-01-13 17:30 --------- d-----w C:&#092;Program Files&#092;REGSHAVE

2008-01-13 17:30 --------- d-----w C:&#092;Program Files&#092;QuickTime

2008-01-06 20:54 --------- d-----w C:&#092;Program Files&#092;Maxis

2008-01-06 19:23 158,208 ----a-w C:&#092;WINDOWS&#092;pchealth&#092;helpctr&#092;bi naries&#092;msconfig.exe

2008-01-05 23:31 150,528 -c--a-w C:&#092;WINDOWS&#092;pchealth&#092;UploadLB&#092;B inaries&#092;UploadM.exe

2008-01-05 20:26 9,728 -c--a-w C:&#092;WINDOWS&#092;inf&#092;unregpn.exe

2008-01-05 20:22 93,184 -c----r C:&#092;WINDOWS&#092;VIEW32.EXE

2008-01-05 20:22 86,016 -c--a-w C:&#092;WINDOWS&#092;unvise32qt.exe

2008-01-05 20:22 73,216 ----a-w C:&#092;WINDOWS&#092;ST6UNST.EXE

2008-01-05 20:22 45,568 ----a-w C:&#092;WINDOWS&#092;UniFish3.exe

2008-01-05 20:22 41,984 -c--a-w C:&#092;WINDOWS&#092;Ctregrun.exe

2008-01-05 20:22 33,280 -c--a-w C:&#092;WINDOWS&#092;DXTool.exe

2008-01-05 20:22 299,520 -c--a-w C:&#092;WINDOWS&#092;uninst.exe

2008-01-05 20:22 26,624 -c--a-w C:&#092;WINDOWS&#092;TBZoom.exe

2008-01-05 20:22 25,600 -c--a-w C:&#092;WINDOWS&#092;twunk_32.exe

2008-01-05 20:22 249,856 ----a-w C:&#092;WINDOWS&#092;Setup1.exe

2008-01-05 20:22 204,800 -c--a-w C:&#092;WINDOWS&#092;alcupd.exe

2008-01-05 20:22 2,058,752 -c--a-w C:&#092;WINDOWS&#092;QT32INST.EXE

2008-01-05 20:22 169,472 -c--a-w C:&#092;WINDOWS&#092;QTW32DEL.EXE

2008-01-05 20:22 165,888 -c--a-w C:&#092;WINDOWS&#092;CTDelLau.exe

2008-01-05 20:22 151,552 -c--a-w C:&#092;WINDOWS&#092;CTDEL.EXE

2008-01-05 20:22 15,360 -c--a-w C:&#092;WINDOWS&#092;TASKMAN.EXE

2008-01-05 20:22 107,008 -c--a-w C:&#092;WINDOWS&#092;PLAY32.EXE

2008-01-05 20:21 135,168 -c--a-w C:&#092;WINDOWS&#092;alcrmv.exe

2008-01-05 19:02 94,208 -c--a-w C:&#092;WINDOWS&#092;ScUnin.exe

2008-01-05 19:02 306,688 ----a-w C:&#092;WINDOWS&#092;IsUninst.exe

2008-01-05 19:02 --------- d-----w C:&#092;Program Files&#092;Railroad Tycoon II

2008-01-03 19:10 99,840 -c--a-w C:&#092;WINDOWS&#092;pchealth&#092;helpctr&#092;bi naries&#092;HelpHost.exe

2008-01-03 19:10 743,936 ----a-w C:&#092;WINDOWS&#092;pchealth&#092;helpctr&#092;bi naries&#092;HelpSvc.exe

2008-01-03 19:10 35,328 -c--a-w C:&#092;WINDOWS&#092;pchealth&#092;helpctr&#092;bi naries&#092;notiflag.exe

2008-01-03 19:10 18,944 -c--a-w C:&#092;WINDOWS&#092;pchealth&#092;helpctr&#092;bi naries&#092;HscUpd.exe

2008-01-03 19:10 158,208 ----a-w C:&#092;WINDOWS&#092;pchealth&#092;helpctr&#092;bi naries&#092;MSConfig .exe

2008-01-03 19:05 98,304 -c--a-w C:&#092;WINDOWS&#092;system32&#092;verifier.exe

2008-01-03 19:05 8,704 -c--a-w C:&#092;WINDOWS&#092;system32&#092;wdfmgr.exe

2008-01-03 19:05 8,704 -c--a-w C:&#092;WINDOWS&#092;system32&#092;uwdf.exe

2008-01-03 19:05 77,824 -c--a-w C:&#092;WINDOWS&#092;system32&#092;usrmlnka.exe

2008-01-03 19:05 69,632 -c--a-w C:&#092;WINDOWS&#092;system32&#092;usrshuta.exe

2008-01-03 19:05 65,536 -c--a-w C:&#092;WINDOWS&#092;system32&#092;wextract.exe

2008-01-03 19:05 61,440 -c--a-w C:&#092;WINDOWS&#092;system32&#092;usrprbda.exe

2008-01-03 19:05 5,632 -c--a-w C:&#092;WINDOWS&#092;system32&#092;winver.exe

2008-01-03 19:05 5,632 ----a-w C:&#092;WINDOWS&#092;system32&#092;write.exe

2008-01-03 19:05 49,664 -c--a-w C:&#092;WINDOWS&#092;system32&#092;w32tm.exe

2008-01-03 19:05 47,104 -c--a-w C:&#092;WINDOWS&#092;system32&#092;WRKGADM.EXE

2008-01-03 19:05 33,792 -c--a-w C:&#092;WINDOWS&#092;system32&#092;vssadmin.exe

2008-01-03 19:05 32,256 -c--a-w C:&#092;WINDOWS&#092;system32&#092;wpabaln.exe

2008-01-03 19:05 30,720 -c--a-w C:&#092;WINDOWS&#092;system32&#092;xcopy.exe

2008-01-03 19:05 17,408 -c--a-w C:&#092;WINDOWS&#092;system32&#092;wpdshextautopla y.exe

2008-01-03 19:05 146,432 ----a-w C:&#092;WINDOWS&#092;system32&#092;WudfHost.exe

2008-01-03 19:05 13,824 -c--a-w C:&#092;WINDOWS&#092;system32&#092;wscntfy.exe

2008-01-03 19:05 119,808 ----a-w C:&#092;WINDOWS&#092;system32&#092;winmine.exe

2008-01-03 19:05 11,776 -c--a-w C:&#092;WINDOWS&#092;system32&#092;winmsd.exe

2008-01-03 19:00 9,216 -c--a-w C:&#092;WINDOWS&#092;system32&#092;subst.exe

2008-01-03 19:00 75,264 -c--a-w C:&#092;WINDOWS&#092;system32&#092;telnet.exe

2008-01-03 19:00 679,936 -c--a-w C:&#092;WINDOWS&#092;system32&#092;sstext3d.scr

2008-01-03 19:00 63,488 -c--a-w C:&#092;WINDOWS&#092;system32&#092;unam4ie.exe

2008-01-03 19:00 610,304 -c--a-w C:&#092;WINDOWS&#092;system32&#092;sspipes.scr

2008-01-03 19:00 51,200 -c--a-w C:&#092;WINDOWS&#092;system32&#092;syncapp.exe

2008-01-03 19:00 47,104 -c--a-w C:&#092;WINDOWS&#092;system32&#092;ssmypics.scr

2008-01-03 19:00 45,056 ----a-w C:&#092;WINDOWS&#092;system32&#092;UninstallBeetle .exe

2008-01-03 19:00 44,544 -c--a-w C:&#092;WINDOWS&#092;system32&#092;tscupgrd.exe

2008-01-03 19:00 4,096 -c--a-w C:&#092;WINDOWS&#092;system32&#092;unlodctr.exe

2008-01-03 19:00 36,864 -c--a-w C:&#092;WINDOWS&#092;system32&#092;syskey.exe

2008-01-03 19:00 31,744 -c--a-w C:&#092;WINDOWS&#092;system32&#092;tracert6.exe

2008-01-03 19:00 3,072 -c--a-w C:&#092;WINDOWS&#092;system32&#092;systray.exe

2008-01-03 19:00 20,992 -c--a-w C:&#092;WINDOWS&#092;system32&#092;ssmarque.scr

2008-01-03 19:00 19,456 -c--a-w C:&#092;WINDOWS&#092;system32&#092;tcpsvcs.exe

2008-01-03 19:00 18,944 -c--a-w C:&#092;WINDOWS&#092;system32&#092;ssmyst.scr

2008-01-03 19:00 16,896 -c--a-w C:&#092;WINDOWS&#092;system32&#092;tsshutdn.exe

2008-01-03 19:00 16,896 -c--a-w C:&#092;WINDOWS&#092;system32&#092;tftp.exe

2008-01-03 19:00 16,384 -c--a-w C:&#092;WINDOWS&#092;system32&#092;tskill.exe

2008-01-03 19:00 15,360 -c--a-w C:&#092;WINDOWS&#092;system32&#092;taskman.exe

2008-01-03 19:00 14,848 -c--a-w C:&#092;WINDOWS&#092;system32&#092;tsdiscon.exe

2008-01-03 19:00 14,848 -c--a-w C:&#092;WINDOWS&#092;system32&#092;tscon.exe

2008-01-03 19:00 14,848 -c--a-w C:&#092;WINDOWS&#092;system32&#092;stimon.exe

2008-01-03 19:00 14,336 -c--a-w C:&#092;WINDOWS&#092;system32&#092;ssstars.scr

2008-01-03 19:00 12,288 -c--a-w C:&#092;WINDOWS&#092;system32&#092;tracert.exe

2008-01-03 19:00 12,288 -c--a-w C:&#092;WINDOWS&#092;system32&#092;tcmsetup.exe

2008-01-03 19:00 105,984 -c--a-w C:&#092;WINDOWS&#092;system32&#092;sysocmgr.exe

2008-01-03 18:59 9,728 -c--a-w C:&#092;WINDOWS&#092;system32&#092;sfc.exe

2008-01-03 18:59 9,728 -c--a-w C:&#092;WINDOWS&#092;system32&#092;reset.exe

2008-01-03 18:59 9,216 -c--a-w C:&#092;WINDOWS&#092;system32&#092;scrnsave.scr

2008-01-03 18:59 8,192 -c--a-w C:&#092;WINDOWS&#092;system32&#092;smbinst.exe

2008-01-03 18:59 77,824 -c--a-w C:&#092;WINDOWS&#092;system32&#092;shrpubw.exe

2008-01-03 18:59 77,312 -c--a-w C:&#092;WINDOWS&#092;system32&#092;sdbinst.exe

2008-01-03 18:59 77,312 -c--a-w C:&#092;WINDOWS&#092;system32&#092;rtcshare.exe

2008-01-03 18:59 704,512 -c--a-w C:&#092;WINDOWS&#092;system32&#092;ss3dfo.scr

2008-01-03 18:59 70,144 -c--a-w C:&#092;WINDOWS&#092;system32&#092;sigverif.exe

2008-01-03 18:59 7,168 -c--a-w C:&#092;WINDOWS&#092;system32&#092;recover.exe

2008-01-03 18:59 67,072 -c--a-w C:&#092;WINDOWS&#092;system32&#092;rdshost.exe

2008-01-03 18:59 62,464 -c--a-w C:&#092;WINDOWS&#092;system32&#092;rdpclip.exe

2008-01-03 18:59 56,832 ----a-w C:&#092;WINDOWS&#092;system32&#092;sol.exe

2008-01-03 18:59 538,624 ----a-w C:&#092;WINDOWS&#092;system32&#092;spider.exe

2008-01-03 18:59 50,176 -c--a-w C:&#092;WINDOWS&#092;system32&#092;reg.exe

2008-01-03 18:59 49,152 -c--a-w C:&#092;WINDOWS&#092;system32&#092;rsmui.exe

2008-01-03 18:59 49,152 -c--a-w C:&#092;WINDOWS&#092;system32&#092;rsm.exe

2007-06-17 07:43 44,544 --sha-w C:&#092;WINDOWS&#092;system32&#092;drwaton.exe

.

Código:
&#60;pre&#62;

----a-w********** 158,208 2008-01-03 19&#58;10&#58;52**C&#58;&#092;WINDOWS&#092;pchealth&#092;helpctr&#092;binaries&#092;MSConfig .exe
&#60;/pre&#62;




((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4



[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#0 92;Windows&#092;CurrentVersion&#092;Run]

"NvCplDaemon"="C:&#092;WINDOWS&#092;system32&#092; NvCpl.dll" [2006-06-01 17:22 7618560]

"nwiz"="nwiz.exe" [2008-01-03 16:02 1519616 C:&#092;WINDOWS&#092;system32&#092;nwiz.exe]

"NvMediaCenter"="C:&#092;WINDOWS&#092;system32&#09 2;NvMcTray.dll" [2006-06-01 17:22 86016]

"LVCOMSX"="C:&#092;WINDOWS&#092;system32&#092;LVCO MSX.EXE" [ ]

"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 12:00 110592 C:&#092;WINDOWS&#092;system32&#092;bthprops.cpl]

"Windows Defender"="C:&#092;Program Files&#092;Windows Defender&#092;MSASCui.exe" [2006-11-03 19:20 866584]



[HKEY_LOCAL_MACHINE&#092;system&#092;currentcontrol set&#092;control&#092;securityproviders]

SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, wowfx.dll



[HKLM&#092;~&#092;startupfolder&#092;C:^Documents and Settings^All Users^Start Menu^Programs^Startup^autorun.exe]

path=C:&#092;Documents and Settings&#092;All Users&#092;Start Menu&#092;Programs&#092;Startup&#092;autorun.exe

backup=C:&#092;WINDOWS&#092;pss&#092;autorun.exeCo mmon Startup



[HKLM&#092;~&#092;startupfolder&#092;C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]

path=C:&#092;Documents and Settings&#092;All Users&#092;Start Menu&#092;Programs&#092;Startup&#092;HP Digital Imaging Monitor.lnk

backup=C:&#092;WINDOWS&#092;pss&#092;HP Digital Imaging Monitor.lnkCommon Startup



[HKLM&#092;~&#092;startupfolder&#092;C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Find Fast.lnk]

path=C:&#092;Documents and Settings&#092;All Users&#092;Start Menu&#092;Programs&#092;Startup&#092;Microsoft Find Fast.lnk

backup=C:&#092;WINDOWS&#092;pss&#092;Microsoft Find Fast.lnkCommon Startup



[HKLM&#092;~&#092;startupfolder&#092;C:^Documents and Settings^User^Start Menu^Programs^Startup^findfast .exe]

path=C:&#092;Documents and Settings&#092;User&#092;Start Menu&#092;Programs&#092;Startup&#092;findfast .exe

backup=C:&#092;WINDOWS&#092;pss&#092;findfast .exeStartup



[HKLM&#092;~&#092;startupfolder&#092;C:^Documents and Settings^User^Start Menu^Programs^Startup^findfast .exe]

path=C:&#092;Documents and Settings&#092;User&#092;Start Menu&#092;Programs&#092;Startup&#092;findfast .exe

backup=C:&#092;WINDOWS&#092;pss&#092;findfast .exeStartup



[HKLM&#092;~&#092;startupfolder&#092;C:^Documents and Settings^User^Start Menu^Programs^Startup^findfast.exe]

path=C:&#092;Documents and Settings&#092;User&#092;Start Menu&#092;Programs&#092;Startup&#092;findfast.exe

backup=C:&#092;WINDOWS&#092;pss&#092;findfast.exeS tartup



[HKLM&#092;~&#092;startupfolder&#092;C:^Documents and Settings^User^Start Menu^Programs^Startup^UDPixel.lnk]

path=C:&#092;Documents and Settings&#092;User&#092;Start Menu&#092;Programs&#092;Startup&#092;UDPixel.lnk

backup=C:&#092;WINDOWS&#092;pss&#092;UDPixel.lnkSt artup



[HKEY_LOCAL_MACHINE&#092;software&#092;microsoft&#0 92;shared tools&#092;msconfig&#092;startupreg&#092;4oD]

C:&#092;Program Files&#092;Kontiki&#092;KHost.exe



[HKEY_LOCAL_MACHINE&#092;software&#092;microsoft&#0 92;shared tools&#092;msconfig&#092;startupreg&#092;avp]

C:&#092;WINDOWS&#092;TEMP&#092;win1F2E .exe



[HKEY_LOCAL_MACHINE&#092;software&#092;microsoft&#0 92;shared tools&#092;msconfig&#092;startupreg&#092;CaAvTray]

C:&#092;Program Files&#092;CA&#092;eTrust EZ Armor&#092;eTrust EZ Antivirus&#092;CAVTray.exe



[HKEY_LOCAL_MACHINE&#092;software&#092;microsoft&#0 92;shared tools&#092;msconfig&#092;startupreg&#092;CAVRID]

C:&#092;Program Files&#092;CA&#092;eTrust EZ Armor&#092;eTrust EZ Antivirus&#092;CAVRID.exe



[HKEY_LOCAL_MACHINE&#092;software&#092;microsoft&#0 92;shared tools&#092;msconfig&#092;startupreg&#092;CTDrive]

C:&#092;WINDOWS&#092;system32&#092;drvxes.dll



[HKEY_LOCAL_MACHINE&#092;software&#092;microsoft&#0 92;shared tools&#092;msconfig&#092;startupreg&#092;HP Component Manager]

C:&#092;Program Files&#092;HP&#092;hpcoretech&#092;hpcmpmgr.exe



[HKEY_LOCAL_MACHINE&#092;software&#092;microsoft&#0 92;shared tools&#092;msconfig&#092;startupreg&#092;HP Software Update]

C:&#092;Program Files&#092;HP&#092;HP Software Update&#092;HPWuSchd2.exe



[HKEY_LOCAL_MACHINE&#092;software&#092;microsoft&#0 92;shared tools&#092;msconfig&#092;startupreg&#092;HPHmon06]



[HKEY_LOCAL_MACHINE&#092;software&#092;microsoft&#0 92;shared tools&#092;msconfig&#092;startupreg&#092;HPHUPD06]



[HKEY_LOCAL_MACHINE&#092;software&#092;microsoft&#0 92;shared tools&#092;msconfig&#092;startupreg&#092;kdx]

C:&#092;Program Files&#092;Kontiki&#092;KHost.exe



[HKEY_LOCAL_MACHINE&#092;software&#092;microsoft&#0 92;shared tools&#092;msconfig&#092;startupreg&#092;letqzsbm]

C:&#092;Program Files&#092;letqzsbm&#092;ponefefu.dll



[HKEY_LOCAL_MACHINE&#092;software&#092;microsoft&#0 92;shared tools&#092;msconfig&#092;startupreg&#092;Load]

C:&#092;WINDOWS&#092;system32&#092;jkkli.exe



[HKEY_LOCAL_MACHINE&#092;software&#092;microsoft&#0 92;shared tools&#092;msconfig&#092;startupreg&#092;lsass]

C:&#092;WINDOWS&#092;lsass .exe



[HKEY_LOCAL_MACHINE&#092;software&#092;microsoft&#0 92;shared tools&#092;msconfig&#092;startupreg&#092;NapsterSh ell]

C:&#092;Program Files&#092;Napster&#092;napster.exe



[HKEY_LOCAL_MACHINE&#092;software&#092;microsoft&#0 92;shared tools&#092;msconfig&#092;startupreg&#092;Printer]

C:&#092;WINDOWS&#092;system32&#092;printer.exe



[HKEY_LOCAL_MACHINE&#092;software&#092;microsoft&#0 92;shared tools&#092;msconfig&#092;startupreg&#092;smgr]





[HKEY_LOCAL_MACHINE&#092;software&#092;microsoft&#0 92;shared tools&#092;msconfig&#092;startupreg&#092;Spoolsv]

C:&#092;WINDOWS&#092;system32&#092;spoolvs.exe



[HKEY_LOCAL_MACHINE&#092;software&#092;microsoft&#0 92;shared tools&#092;msconfig&#092;startupreg&#092;WMC_AutoU pdate]



[HKEY_LOCAL_MACHINE&#092;software&#092;microsoft&#0 92;shared tools&#092;msconfig&#092;startupreg&#092;xanatkbc]

regsvr32 /u C:&#092;Documents and Settings&#092;All Users&#092;Application Data&#092;xanatkbc.dll



[HKEY_LOCAL_MACHINE&#092;software&#092;microsoft&#0 92;shared tools&#092;msconfig&#092;services]

"Spooler"=2 (0x2)



R1 CTSYN;Creative S/W Synth;C:&#092;WINDOWS&#092;system32&#092;drivers&# 092;CTSYN.SYS [1999-06-16 01:00]

S3 gel90xne;gel90xne;C:&#092;DOCUME~1&#092;User&#092; LOCALS~1&#092;Temp&#092;gel90xne.sys []

S4 avp ;avp ;"C:&#092;Program Files&#092;Kaspersky Lab&#092;Kaspersky Anti-Virus 7.0&#092;avp .exe" []

S4 avp ;avp ;"C:&#092;Program Files&#092;Kaspersky Lab&#092;Kaspersky Anti-Virus 7.0&#092;avp .exe" []



[HKEY_CURRENT_USER&#092;software&#092;microsoft&#09 2;windows&#092;currentversion&#092;explorer&#092;m ountpoints2&#092;E]

&#092;Shell&#092;AutoRun&#092;command - E:&#092;autorun.exe

&#092;Shell&#092;setup&#092;command - E:&#092;setup.exe



.

Contents of the &#39;Scheduled Tasks&#39; folder

"2008-01-17 00:00:00 C:&#092;WINDOWS&#092;Tasks&#092;At1.job"

- C:&#092;WINDOWS&#092;system32&#92;&#48;KK8DX4O.ex e

"2008-01-20 09:00:00 C:&#092;WINDOWS&#092;Tasks&#092;At10.job"

- C:&#092;WINDOWS&#092;system32&#92;&#48;KK8DX4O.ex e

"2008-01-20 10:00:00 C:&#092;WINDOWS&#092;Tasks&#092;At11.job"

- C:&#092;WINDOWS&#092;system32&#92;&#48;KK8DX4O.ex e

"2008-01-20 11:00:00 C:&#092;WINDOWS&#092;Tasks&#092;At12.job"

- C:&#092;WINDOWS&#092;system32&#92;&#48;KK8DX4O.ex e

"2008-01-20 12:00:00 C:&#092;WINDOWS&#092;Tasks&#092;At13.job"

- C:&#092;WINDOWS&#092;system32&#92;&#48;KK8DX4O.ex e

"2008-01-20 13:00:02 C:&#092;WINDOWS&#092;Tasks&#092;At14.job"

- C:&#092;WINDOWS&#092;system32&#92;&#48;KK8DX4O.ex e

"2008-01-20 14:00:00 C:&#092;WINDOWS&#092;Tasks&#092;At15.job"

- C:&#092;WINDOWS&#092;system32&#92;&#48;KK8DX4O.ex e

"2008-01-20 15:00:00 C:&#092;WINDOWS&#092;Tasks&#092;At16.job"

- C:&#092;WINDOWS&#092;system32&#92;&#48;KK8DX4O.ex e

"2008-01-20 16:00:00 C:&#092;WINDOWS&#092;Tasks&#092;At17.job"

- C:&#092;WINDOWS&#092;system32&#92;&#48;KK8DX4O.ex e

"2008-01-21 17:00:00 C:&#092;WINDOWS&#092;Tasks&#092;At18.job"

- C:&#092;WINDOWS&#092;system32&#92;&#48;KK8DX4O.ex e

"2008-01-22 18:00:00 C:&#092;WINDOWS&#092;Tasks&#092;At19.job"

- C:&#092;WINDOWS&#092;system32&#92;&#48;KK8DX4O.ex e

"2008-01-17 01:00:00 C:&#092;WINDOWS&#092;Tasks&#092;At2.job"

- C:&#092;WINDOWS&#092;system32&#92;&#48;KK8DX4O.ex e

"2008-01-22 19:00:00 C:&#092;WINDOWS&#092;Tasks&#092;At20.job"

- C:&#092;WINDOWS&#092;system32&#92;&#48;KK8DX4O.ex e

"2008-01-22 20:00:00 C:&#092;WINDOWS&#092;Tasks&#092;At21.job"

- C:&#092;WINDOWS&#092;system32&#92;&#48;KK8DX4O.ex e

"2008-01-22 21:00:00 C:&#092;WINDOWS&#092;Tasks&#092;At22.job"

- C:&#092;WINDOWS&#092;system32&#92;&#48;KK8DX4O.ex e

"2008-01-22 22:00:00 C:&#092;WINDOWS&#092;Tasks&#092;At23.job"

- C:&#092;WINDOWS&#092;system32&#92;&#48;KK8DX4O.ex e

"2008-01-16 23:00:00 C:&#092;WINDOWS&#092;Tasks&#092;At24.job"

- C:&#092;WINDOWS&#092;system32&#92;&#48;KK8DX4O.ex e

"2008-01-09 02:00:01 C:&#092;WINDOWS&#092;Tasks&#092;At3.job"

- C:&#092;WINDOWS&#092;system32&#92;&#48;KK8DX4O.ex e

"2008-01-09 03:00:00 C:&#092;WINDOWS&#092;Tasks&#092;At4.job"

- C:&#092;WINDOWS&#092;system32&#92;&#48;KK8DX4O.ex e

"2007-12-29 04:01:30 C:&#092;WINDOWS&#092;Tasks&#092;At5.job"

- C:&#092;WINDOWS&#092;system32&#92;&#48;KK8DX4O.ex e

"2007-09-30 04:00:00 C:&#092;WINDOWS&#092;Tasks&#092;At6.job"

- C:&#092;WINDOWS&#092;system32&#92;&#48;KK8DX4O.ex e

"2007-09-30 05:00:00 C:&#092;WINDOWS&#092;Tasks&#092;At7.job"

- C:&#092;WINDOWS&#092;system32&#92;&#48;KK8DX4O.ex e

"2007-11-28 07:00:00 C:&#092;WINDOWS&#092;Tasks&#092;At8.job"

- C:&#092;WINDOWS&#092;system32&#92;&#48;KK8DX4O.ex e

"2007-10-23 07:00:00 C:&#092;WINDOWS&#092;Tasks&#092;At9.job"

- C:&#092;WINDOWS&#092;system32&#92;&#48;KK8DX4O.ex e

"2008-01-23 15:24:56 C:&#092;WINDOWS&#092;Tasks&#092;MP Scheduled Scan.job"

- C:&#092;Program Files&#092;Windows Defender&#092;MpCmdRun.exe

.

************************************************** ************************



catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-01-23 15:37:08

Windows 5.1.2600 Service Pack 2 NTFS



scanning hidden processes ...



scanning hidden autostart entries ...



scanning hidden files ...



scan completed successfully

hidden files: 0



************************************************** ************************

.


ayudaaaa&#33;&#33;&#33;&#33;&#33;